STABLECOIN FLOAT $313.58B◆ NATIVE USDC ON BASE $4.31B◆ DEFI TVL $95.61B◆ THE PUBLIC LEDGER OF MACHINE MONEY — AGENTICFINANCEGRAPH.COM◆

Home / Detections

Detections · found by our own detectors

What our detectors caught.

Every row below is a detection: something that happened at a time, with evidence behind it — a burst of registrations minted by one address inside an hour, an agent paying the same counterparty over and over, an endpoint that has never once answered, an identity that changed owner. A low score is not a detection and you will not find one here; that is a measurement, and it lives on the data page.

A handful of detections are also incidents: a harm, happening to somebody, recently. They are shown first and in red. Most days there are none, and saying so is the point.

Live incidents

—

Checking…

Detections logged — Detectors run hourly against measurements we already hold — no external calls, so this costs nothing to keep current. loading…
Last 7 days — Dated by when the event happened, not when we noticed it — a backfill does not make last week look busy. rolling 7 days
Major — Reserved for scale: a burst of 500+ registrations from one address in one hour, and the like. Severity is size, not harm. severity: major
Kinds firing — Detectors that have found something. Several more are armed and quiet, which is the correct state for a detector with nothing to report. distinct kinds

By kind

Loading…

The log · newest first

Loading detections…

— · JSON API · live incidents only · how the ranks work

Detection, incident, and the difference.

New, 24 September 2026: drain_pattern. A payment at least five times the agent’s previous largest, at least $250, to an address it had never paid, after at least three earlier payments. It is the shape a drained agent wallet leaves, and also the shape of a legitimate one-off purchase, so it is always a detection for a human to read, never an incident, and the agent is never named publicly. The reasoning →

A detection is an occurrence: it happened at a time, we can point at the evidence, and a reader could in principle have watched it happen. A detector that fired on a state would turn this page into a scoreboard, and a scoreboard of low scores is worth nothing to anybody. "This agent has never answered a probe" sits on the edge — it is a state — so it only becomes a detection after a streak of failures with no success ever recorded, which makes it an event about our own repeated attempts rather than a verdict on the agent.

An incident is a detection that is also a harm, and recent. Three kinds qualify: a retry storm, where an agent pays the same counterparty over and over and somebody is paying the fees for every attempt; an identity that changed owner under a binding people rely on, so the history they trust now belongs to somebody else; and signing delegated to an implementation nobody has vetted. Each counts as live for 72 hours, then stays in the log as a detection.

A mint burst is never an incident, however large. One address minting hundreds of registrations in an hour is exactly what a platform issuing identities for its users looks like. It is worth logging because it changes what a registration count means — the headline is measuring a script, not an ecosystem — but it harms nobody. This page called it a sybil burst until September 2026, and that was wrong: sybil asserts intent, and our own definition says the opposite.

Detectors that are armed and currently silent still matter. god_key_unknown_7702 fires when a wallet delegates to an implementation outside a curated allowlist, and that allowlist ships empty on purpose — until a human has read a contract and can say why it belongs there, calling an unknown implementation a god key would be a guess, and this site does not publish guesses. It reports nothing today, and that is the honest answer rather than a broken one.